
Skill ScannerOpen-source security scanner that audits AI agent skills for prompt injection and malicious patterns.
Преглед
Ключови функции
- Prompt injection pattern detection
- Data exfiltration heuristics
- Malicious code pattern scanning
- SARIF report output
- CI/CD pipeline integration
- Extensible rule set
Цени
- Модел
- Freemium
- Категория
- Software Testing (QA) Agents
- Оценка
- 4.7 / 5 (6)
Случаи на употреба
Vet third-party agent skills before deployment
Scan external skills and plugins for prompt injection patterns and suspicious code before adding them to your AI agent, reducing the risk of compromised integrations.
Enforce security gates in CI/CD
Integrate Skill Scanner into build pipelines using its SARIF output to automatically block pull requests that introduce risky skill manifests or instructions.
Surface findings in GitHub code scanning
Pipe SARIF reports into GitHub code scanning or security dashboards so developers and security teams can triage agent skill vulnerabilities alongside other code issues.
Harden in-house skills with custom rules
Extend the rule set to match organization-specific threat models, ensuring internally built agent skills meet baseline checks for data exfiltration and malicious patterns.
Плюсове и минуси
Плюсове
- Free and open source
- Targets agent-specific threats like prompt injection
- SARIF output integrates with existing security tools
- Useful for CI/CD security gates
- Customizable detection rules
Минуси
- Requires technical setup and CLI familiarity
- Static analysis cannot catch all runtime attacks
- Coverage depends on community-maintained rules
Отзиви
Средно от 6 оценки.
Влез, за да оставиш отзив.
Does the job
Pretty happy overall. Extensible rule set just works and sARIF output integrates with existing security tools. Static analysis cannot catch all runtime attacks can be annoying, but no dealbreakers — I'd recommend it to a friend without hesitating.
Use it every day
Honestly didn't expect to like it this much. SARIF report output is exactly what I needed, and free and open source. I do wish static analysis cannot catch all runtime attacks, but I reach for it almost every day now and it just clicks.
Use it every day
Honestly didn't expect to like it this much. SARIF report output is exactly what I needed, and useful for CI/CD security gates. but I reach for it almost every day now and it just clicks.
Years in this space
I've evaluated a lot of these over the years. What stands out here is sARIF report output — handled better than most — and free and open source. Worth the time if this is your use case.
Use it every day
Honestly didn't expect to like it this much. SARIF report output is exactly what I needed, and targets agent-specific threats like prompt injection. I do wish coverage depends on community-maintained rules, but I reach for it almost every day now and it just clicks.
Solid for our team
We rolled this out across the team last quarter and useful for CI/CD security gates. Data exfiltration heuristics fits neatly into how we already work, and sARIF report output removed a step we used to do by hand. Requires technical setup and CLI familiarity, which is the main caveat, but it has held up under daily use.
Въпроси
How much does Skill Scanner cost and what's the licensing model?
Skill Scanner is free and open source, so there are no licensing fees. You can self-host and run it as part of your own workflows, with the trade-off that you handle setup, maintenance, and any rule customization yourself.
What threats can it detect, and what are its limitations?
It performs static analysis on skill manifests, instructions, and bundled code to flag prompt injection patterns, data exfiltration heuristics, and suspicious code. As a static tool, it can't catch all runtime attacks, and detection quality depends on the community-maintained or custom rule set.
How does Skill Scanner integrate with CI/CD and existing security tooling?
It outputs findings in SARIF, the standard format consumed by tools like GitHub code scanning, security dashboards, and code review workflows. This makes it straightforward to wire into CI/CD pipelines as a security gate alongside other static analysis tools.
Задай въпрос
Алтернативи на Software Testing (QA) Agents
CarbonCopies AI
Software Testing (QA) Agents
AI двойници имитират взаимодействия на потребителите, за да извършват автоматизирано тестирование на UX и функционална ефективност и да детектират грешки в програми и уебсайтове.
Diffblue Cover
Software Testing (QA) Agents
Автономен агент на AI, предназначен за генериране и поддържане на единични изпитания за Java на мащаби с гарантирана точност.
PentAGI
Software Testing (QA) Agents
Open-source autonomous penetration testing agents that run 20+ security tools in an isolated Docker sandbox with memory and web intelligence.
Flowtest AI
Software Testing (QA) Agents
Агент за интелектуална помощ, който наблюдава уебсайтове чрез изкуствено симулирано потребителско взаимодействие с цел детектиране на проблеми и гарантиране на работоспособност.
Keploy
Software Testing (QA) Agents
Отворен‑източников AI агент, който аутоматизира и поддържа единични, интеграционни и API тестира с моки.
Trending now
Reducto AI
AI Agent Development Platforms
Document intelligence API that parses, splits, OCRs, and extracts structured data from complex PDFs, slides, and spreadsheets.
AdCrier
Marketing & Advertising
Раждане на спонсорираните отговори, заплатено за клик.
Pin AI
Workflow automation
Agentic AI recruiter that automates sourcing, screening, and outreach to accelerate hiring.
Midjourney
Image Generation
Генерирайте поразителни изображения от текст









